WORDFENCE-07bccf56-99b2-42e6-93ab-606af65e6cac
medium
📛 Threat Title
Site5 Various Affected Themes (Various Versions) - Email Spoofing
Description
Various Site5 themes for WordPress are vulnerable to Email Spoofing. This makes it possible for unauthenticated attackers to modify email addresses to potentially perform future attacks on other users. Affected software — theme: boldy (affected: [*, 2.0)); theme: rockwell (affected: *); theme: webfolio (affected: [*, 2.0)); theme: simplo (affected: *); theme: Wise (affected: *); theme: prosume (affected: [*, 2.0)); theme: diary (affected: [*, 2.0)); theme: designpile (affected: *); theme: journalcrunch (affected: [*, 2.0)); theme: alltuts (affected: [*, 2.0)); theme: colorbold (affected: *); theme: xmas (affected: *). CVSS 5.3 (Medium) — CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N.
Indicators of Compromise (0)
No indicators of compromise on this threat.
References (2)
Remediations (12)
-
Wordfence remediation: boldyWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: rockwellWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
-
Wordfence remediation: webfolioWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: simploWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
-
Wordfence remediation: WiseWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
-
Wordfence remediation: prosumeWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: diaryWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: designpileWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
-
Wordfence remediation: journalcrunchWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: alltutsWordfence
Update to version 2.0, or a newer patched version
-
Wordfence remediation: colorboldWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
-
Wordfence remediation: xmasWordfence
No known patch available. Please review the vulnerability's details in depth and employ mitigations based on your organization's risk tolerance. It may be best to uninstall the affected software and find a replacement.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.